Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Zimbra has released patches to address nine security vulnerabilities, including a critical SNMP command injection flaw and several XSS vulnerabilities. These fixes are vital to mitigate potential code execution and email exfiltration risks, particularly given the historical exploitation of XSS vulnerabilities in the email software.
Zimbra has released security updates to address multiple vulnerabilities within its email server software. These updates are crucial for maintaining system security and preventing potential exploitation. The vulnerabilities range from command injection to cross-site scripting (XSS) flaws.
Specifically, a critical SNMP command injection vulnerability exists within the SNMP monitoring component when SNMP notifications are enabled. Additionally, four XSS vulnerabilities have been patched in the Classic Web Client. These include a stored XSS vulnerability allowing malicious attachment filenames to execute script, an XSS vulnerability where crafted fields could execute a malicious script, an XSS vulnerability where a crafted field could execute a malicious script when rendered, and an XSS vulnerability where crafted attachments could execute a malicious script when rendered.
Separately, a mail forwarding restriction bypass (CVE-2026-50055) has also been addressed, potentially allowing authenticated users to exfiltrate email despite restrictions. Rapid7 security researcher Jonah Burgess discovered and reported the SNMP command injection vulnerability. The company has limited information disclosure regarding the fixes, adhering to industry best practices. Despite the lack of active exploitation reports for these vulnerabilities, XSS flaws in Zimbra have historically been exploited by malicious actors, highlighting the importance of prompt patching.
